Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Assign computers behind pfsense to WAN interfaces

    Scheduled Pinned Locked Moved NAT
    14 Posts 3 Posters 5.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      lithgow
      last edited by

      WAN1 interface has 8 static ips
      WAN2 interface has 1 dynamic IP

      I was wanting to assign one of my block to computer 1, if I use VIP and 1:1 NAT will I still have to bother with assigning WAN1 to computer 1, using the method you gave?

      Thanks for the answer it is much appreciated :)

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        1:1 NAT is bidirection.

        If you 1:1 NAT something then it will always go out the WAN from which the mapping is.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • L
          lithgow
          last edited by

          I tried to setup 1:1 NAT

          My router ip is 78...105 and the ip I was wanting one of my computers to be was 78...110. In 1:1 NAT I set ip to 78...110/32 forwards to 192.168.0.220/32 but this didn't allow any traffic out from the computer, on deleting the entry it was working again.

          What have I done wrong?

          ps. I was told my connection is on the /29 allocation

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            Can you show screenshots of all the pages that are relevant?
            (1:1 NAT, VIP, firewall WAN and LAN)
            Are you using Advanced outbound NAT?

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • L
              lithgow
              last edited by

              I'm using Automatic outbound NAT rule generation (IPsec passthrough).

              When I tried to add a CARP VIP it informed me that I can't set that ip as its not on the same subnet.

              I currently have 2 modems DMZ'd to my pfsense box, I do have the option of half-bridge but I don't think I am able to see modem status when I set this option which is the main reason I do not use it.

              Thanks again for your help :)

              1 Reply Last reply Reply Quote 0
              • GruensFroeschliG
                GruensFroeschli
                last edited by

                Like now it wont work because your 1:1 NATing an IP that does not exist.
                –> You need to create a VIP which will be used in the 1:1 NAT rule.

                Can you set the CARP-VIP again and show a screenshot of how you set it up?
                Please be aware (there is a note on the config page too) that if you configure a CARP-VIP you have to set the correct subnet.
                NOT /32

                (also if you search the forum for this exact problem you will find http://forum.pfsense.org/index.php/topic,9057.0.html in which i wrote the solution to this problem just a few days ago)

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • L
                  lithgow
                  last edited by

                  I had a look at the thread and tried to setup the VIP but I had the same problem that I had earlier…

                  The following input errors were detected:

                  * Sorry, we could not locate an interface with a matching subnet for 78.32.215.110/29. Please add an ip in this subnet on a real interface.

                  1 Reply Last reply Reply Quote 0
                  • GruensFroeschliG
                    GruensFroeschli
                    last edited by

                    How is your WAN set up?
                    Are you using the pfSense to authenticate the PPPoE?
                    Because this would be a Problem: PPPoE WAN's are /32 IP's.
                    Meaning you cannot have a CARP-Type VIP on such a WAN.

                    Try using a PARP-type VIP.

                    We do what we must, because we can.

                    Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                    1 Reply Last reply Reply Quote 0
                    • L
                      lithgow
                      last edited by

                      Router 1 192.168.1.1  -> eth1 192.168.1.4 (DMZ) -> WAN1
                      Router 2 192.168.10.1 -> eth2 192.168.10.4 (DMZ) -> WAN2

                      I'm not using it to do pppoe.

                      I tried a PARP VIP but this had the same effect of no Internet access on the computer I assigned the ip to.

                      1 Reply Last reply Reply Quote 0
                      • H
                        hoba
                        last edited by

                        Reboot the device in front of the ProxyARP IP or dump it's ARP cache. Often it's just an ARP issue of the device in front of you when adding/changing virtual IPs.

                        1 Reply Last reply Reply Quote 0
                        • L
                          lithgow
                          last edited by

                          Unfortunately that didn't work either :(

                          So I don't really know whats going wrong here, would it work if I used pppoe? The only issue I have with that is I can't see my modems config pages and can't check what speed on the dsl I'm getting :(

                          1 Reply Last reply Reply Quote 0
                          • L
                            lithgow
                            last edited by

                            I am still getting this problem, I don't know if anyone can help…

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.